|
aku x dapat nak del virus dlm pendrive aku...
virus tu document.exe
aku da try format tp x leh... file tu protect...
so how? |
|
|
|
|
|
|
|
Reply #1 Rempit_25's post
guna unlocker kat fileforum.com |
|
|
|
|
|
|
|
Document.exe - Dangerous
--------------------------------------------------------------------------------
document.exe
Document.exe is a mass-mailing worm W32.Shima-A.
Document.exe tries to terminate antiviral programs installed on a user computer.
Document.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%Windows%\Document.zip
C:\Document.exe |
|
|
|
|
|
|
|
kao pakai le anti virus.....mesti boleh..tapi kao kena boot dlm safe mode.. |
|
|
|
|
|
|
|
Originally posted by razhar at 6-8-2008 01:07 AM
guna unlocker kat fileforum.com
aku da guna...tp still x leh nak del...
antivirus pun x dapat nak buang....
cam ne nie |
|
|
|
|
|
|
|
kalau dah degil sangat.. cucuk je pendrive tu kat pc yg ada os linux.... remove all partion + boot .. lepas tu create new partion..abis cerita |
|
|
|
|
|
|
|
ko dah try scan ngan mane2 spyware applications? |
|
|
|
|
|
|
|
kalo takleh format, guna aje hdd wipe atau kill disk.
cari kat sini : www.hddguru.com |
|
|
|
|
|
|
|
Originally posted by Rempit_25 at 6-8-2008 12:53 AM
aku x dapat nak del virus dlm pendrive aku...
virus tu document.exe
aku da try format tp x leh... file tu protect...
so how?
Mula2 kat Folder options, setkan supaya show all hidden system files.
Masuk thumbdrive tu and tengok ada tak autorun.inf. Kalau ada, delete tu dulu. Takyah tutup explorer window tu.
Then kat task manager, kill semua DOCUMENT.EXE yg ada.
Masuk semula ke thumbdrive and delete DOCUMENT.EXE tu.
Buat search kat PC... cari autorun.inf... delete SEMUA.
Kemudian scan semula in Safe Mode PC tu... harap2 explorer.exe and calc.exe ko pun tak infected ngan virus tu. |
|
|
|
|
|
|
|
Originally posted by 0001 at 6-8-2008 11:33
Mula2 kat Folder options, setkan supaya show all hidden system files.
Masuk thumbdrive tu and tengok ada tak autorun.inf. Kalau ada, delete tu dulu. Takyah tutup explorer window tu.
Then ...
wa rasa dia punya calc.exe tu musti dah dijangkiti......calc.exe ni adalah default yg akan dijangkiti.. |
|
|
|
|
|
|
|
emm sepatutnya unlocker dah bereskan dah perkara ni.. atau pun dia bagi pilihan nak delete masa reboot atau tidak.. |
|
|
|
|
|
|
|
bai yg kena jangkit tu..sila baca article nih ye.. -
"It's a overwriting virus, programmed in Visual Basic 6.
It will add itself in the registry as
H K E Y _ L O C A L _ M A C H I N E \ S O F T W A R E \ M I C R O S O F T \ W I N D O W S \ C U R R E N T V E R S I O N \ R U N \ E x p l o r e r
---> terminate running processes and remove this value.
It will OVERWRITE calculator programs from windows !
Don't start calc - or you will get infected again.
It copies itself in the windows folder as calc.exe, config_.com (file is hidden!), mscalc.exe and WINDOWS.exe. All files having a filesize of 40960 bytes.
ATTENTION: it also overwrites OTHER EXEFILES! Means if you start a infected executable it will "strip" the virus code out of this file and will start it uninfected, BUT WILL INFECTED IN THE SAME TIME ANOTHER EXECUTABLE!" |
|
|
|
|
|
|
|
tapi musti dibuat dlm komputer bai berada dlm SAFE MODE... |
|
|
|
|
|
|
|
selepas sudah..bai masuk regedit (run-regedit)..bai cari HKEY_LOCAL_MACHINE entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Explorer
<Windows folder>\config_.com
bai delete -<Windows folder>\config_.com |
|
|
|
|
|
|
|
bai musti2 guna unlocker untuk bunuh document.exe..bai kena pilih option unlock,sebelum itew bai kena highlight file tu..selepas pilih unlock...exit then bai guna unlocker semula untuk pilih option KILL../DELETE... |
|
|
|
|
|
|
| |
|